Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to probe global skill directories under the user's home folder to infer an installation prefix, which exceeds what is necessary for fulfilling a workspace-scoped design-skill creation task. That expands filesystem discovery beyond the current project and can expose information about other installed tools, platforms, or user environment details without a clear need or explicit consent.
